Sample viewer

vx.netlux.org/Virus.DOS.Tchantches.3303

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:24.044999038Z 42 PC: 130a8 | Get date 0x130a8: mov al, 0xc
0x130aa: and cx, 0x7f
0x130ad: mul cl
0x130af: mov bl, dl
0x130b1: mov cl, dh
0x130b3: add ax, cx
0x130b5: mov cl, 0x1f
0x130b7: mul cx
0x130b9: mov cl, bl
0x130bb: add ax, cx
0x130bd: pop bx
0x130be: pop cx
0x130bf: pop dx
0x130c0: ret
0x130c1: mov bx, 0x39a
0x130c4: mov cx, 0x9ba
0x130c7: call 0x13ae7
0x130ca: jmp 0x130fb
0x130cc: sti
0x130cd: jl 0x13097
2018-12-17T23:04:24.057718588Z 98 PC: 12e73 | Get current PSP
2018-12-17T23:04:24.06164246Z 250 PC: 12efc | UNKNOWN!
2018-12-17T23:04:24.062738889Z 48 PC: 12f0f | Get DOS version
2018-12-17T23:04:24.064956953Z 82 PC: 12f17 | Get DOS internal pointers (SYSVARS)
2018-12-17T23:04:24.066995162Z 98 PC: 12f2a | Get current PSP
2018-12-17T23:04:24.068719191Z 74 PC: 12f4a | Reallocate memory
2018-12-17T23:04:24.070924785Z 72 PC: 12f54 | Allocate memory
2018-12-17T23:04:24.074200749Z 53 PC: 12f8b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:24.076804224Z 42 PC: 130a8 | Get date 0x130a8: mov al, 0xc
0x130aa: and cx, 0x7f
0x130ad: mul cl
0x130af: mov bl, dl
0x130b1: mov cl, dh
0x130b3: add ax, cx
0x130b5: mov cl, 0x1f
0x130b7: mul cx
0x130b9: mov cl, bl
0x130bb: add ax, cx
0x130bd: pop bx
0x130be: pop cx
0x130bf: pop dx
0x130c0: ret
0x130c1: mov bx, 0x39a
0x130c4: mov cx, 0x9ba
0x130c7: call 0x13ae7
0x130ca: jmp 0x130fb
0x130cc: sti
0x130cd: jl 0x13097
2018-12-17T23:04:24.080153161Z 37 PC: 12fbd | Set interrupt vector (Interrupt = '33' AKA 'Random read')